Back to skill

Security audit

node-connect

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OpenClaw connection troubleshooting guide, but it gives under-scoped device approval instructions that could authorize the wrong device.

Read this skill carefully before installing. Its diagnostics are generally appropriate, but do not let it approve device pairings automatically. Treat every `openclaw devices approve` command as state-changing unless verified otherwise, and approve only a request ID you have confirmed out of band belongs to the intended device.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:100
Finding

Unverified Approval of the Latest Device Pairing Request

Content
View full analysis
``` ``` ### Technical Analysis The skill instructs the operator to execute `openclaw devices approve --latest` while describing it as “preview only.” The command invokes an approval operation rather than an explicitly read-only inspection operation. The guidance therefore creates a risk that the latest pending request will be authorized immediately, contrary to the operator's expectation. The instructions also do not require verification of the requesting device's identity, fingerprint, ownership, challenge code, or other identifying attributes before approval. Selecting a request solely because it is the latest is unsafe when an attacker can reach the pairing endpoint and submit a concurrent request. The subsequent explicit approval by request ID does not mitigate the first command if `approve --latest` already changes authorization state. ### Attack Path 1. The gateway is exposed through a LAN, tailnet, public URL, or another route reachable by an attacker. 2. The attacker submits an unauthorized device-pairing request. 3. The attacker times the request so that it is the latest pending request when an operator begins troubleshooting. 4. The operator follows the skill and executes `openclaw devices approve --latest`, believing the command is only a preview. 5. If the command performs the operation indicated by its name, the attacker's device is approved without identity verification. 6. The unauthorized device can then exercise whatever gateway or node capabilities are granted to paired devices. Exploitati ...[truncated 687 chars]
Remediation
View remediation
``` 5. Clearly warn that every `approve` command changes authorization state. 6. If supported, reject unknown requests, expire stale requests quickly, rate-limit pairing attempts, and restrict the pairing endpoint to the intended network route. 7. Avoid “latest request” selection for security-sensitive operations because request ordering can be manipulated by concurrent or attacker-generated requests. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.